A downloadable AI model cannot be recalled. Once a lab publishes an open-weight model, anyone can copy it, run it on their own hardware, and keep it forever, whatever the publisher later decides. That property drives the fight over cyber risk, and Nathan Lambert, writing in his Interconnects newsletter, argues the fight is being conducted badly.
The post is an argument, not a study. It offers no new measurement, no incident data and no benchmark of its own. Lambert’s claim is about the quality of the debate, which is a separate matter from who is winning it, and the critique can hold even if his reading of the evidence does not.
He sorts the participants into three groups. The first is frontier lab leadership and the U.S. national security community, who treat open weights as a danger to society. The second is Western voices who say open models help defenders and that banning them makes the world less safe. Lambert places himself there, alongside Hugging Face and the researcher Joshua Saxe. The third is the Chinese companies that keep publishing open models with strong cyber skills.
His sharpest complaint targets the first group’s latest output: Anthropic’s report on the risk of pointing GLM-5.3 at offensive hacking. Lambert calls the technical research largely reasonable. What he faults is what the report leaves out: what happens if open models are banned, and why Chinese companies decide such models are safe to release. He adds that Western commentary rarely tries to understand how those companies weigh risk, and often settles for the line that they do not care about safety.
On the evidence, he is cautious. Public records, he says, document closed models as the source of most cyber attacks so far. He offers two readings and says years will pass before anyone knows which is right: perhaps open and closed models are both easy to misuse, or perhaps few bad actors want to launch loud attacks on critical systems. He concedes that closed models may be safer in the limit, and says he has much to learn about how the security world works. He does not claim to have settled the matter.
The policy consequence he draws is a demand for consistency. If open models should be banned to slow the spread of cyber capability, he argues, public APIs for frontier closed models would logically need to go too, because their abilities grow faster than their guardrails. Banning only the open side, in his view, widens the gap between attackers and defenders. He also notes that some government networks, cut off from the internet, can run only open-weight models today.
The GLM-5.3 passage holds two separate claims. The first is about capability: when Claude Mythos was announced, it was previewed as a different kind of cyber weapon altogether, and Lambert says GLM-5.3 by all measures crosses that threshold. The second is about observation: more than a month after its weights were released, he sees little public evidence that anything has changed. His case lives in the distance between those claims.
That distance has two possible readings, and the post does not separate them. Either the harm has not arrived, or it has arrived where the public cannot see it. Lambert addresses the second reading only indirectly, noting that people pressing for action often cite classified briefings he calls at odds with public information. Briefings no outsider can check cannot be weighed against a public record, which is why this debate stalls.
He closes with a bet. Those predicting that open models will cause new, severe harm to cyber infrastructure have made a falsifiable claim, he says, and he thinks they will be wrong. He allows that a leaked Mythos would bring more incidents, though he reads that as faster change rather than a break from the past.
Teams that depend on open-weight models for security work should watch the public incident record over the next quarter. Lambert’s argument stands or falls on whether it stays quiet.
Interconnects (interconnects.ai), by Nathan Lambert, published 6 October 2026 according to secondary indexing, as the post itself carries no date.